Legal

Data Protection And Compliance

Last updated: 27 July 2026

At nVektor, protecting customer and end-user data is a core part of how we design and operate our service.

We are committed to supporting our customers’ compliance with applicable privacy and data protection laws, including the GDPR, UK GDPR, CCPA and other laws that may apply to their use of nVektor.

This page provides a plain-English summary of our approach. Our legally binding commitments are set out in our Terms of Service and Data Processing Addendum.

Our Role

nVektor provides tracking, attribution, event processing and reporting services to ecommerce businesses.

When we process personal data collected through a customer’s website or store:

  • the customer generally acts as the controller, business or equivalent party;
  • nVektor generally acts as the processor, service provider or equivalent party;
  • nVektor processes that data to provide the service and follow the customer’s documented instructions.

Our customers remain responsible for their relationship with their shoppers and website visitors, including providing appropriate privacy and cookie notices, obtaining required consent and responding to privacy requests.

Our Commitments

Where nVektor processes personal data on behalf of a customer, we commit to:

Process Data Only for Agreed Purposes

We process customer personal data only as necessary to provide, secure, support and maintain the nVektor service, follow documented customer instructions and comply with applicable law.

We do not sell end-user personal data or use it for unrelated independent advertising purposes.

Protect Data

We maintain reasonable technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss or destruction.

These measures may include:

  • restricted access to production systems;
  • authentication and access controls;
  • secure handling of credentials and secrets;
  • encryption in transit where supported;
  • logging and monitoring;
  • backup and recovery practices;
  • incident-response procedures;
  • confidentiality obligations for personnel.

No online system can be guaranteed to be completely secure, but we take data protection and service security seriously.

Maintain Confidentiality

Personnel authorised to access customer personal data are required to handle it confidentially and only for legitimate business purposes.

Access is limited according to role and operational need.

Notify Customers of Security Incidents

If we become aware of a security incident affecting personal data processed on behalf of a customer, we will notify the affected customer without undue delay and provide reasonably available information needed to help the customer meet its own obligations.

Support Privacy Rights

Customers are responsible for receiving and responding to privacy requests from their shoppers and website visitors.

Where required, nVektor will reasonably assist customers with requests to access, correct, delete, restrict or otherwise exercise rights relating to personal data processed through the service.

Use Subprocessors Responsibly

nVektor may use trusted service providers to host, secure, monitor, maintain and support the service.

We require subprocessors that process customer personal data to be subject to appropriate confidentiality, security and data protection obligations.

Our current subprocessor list is available to customers upon written request. We will provide notice of intended additions or replacements where required by applicable law or our Data Processing Addendum.

Support International Data Transfers

nVektor and its service providers may process data in countries outside the country where a customer or end user is located.

Where required, we use recognised legal safeguards for international transfers, which may include Standard Contractual Clauses, the UK International Data Transfer Addendum or another lawful transfer mechanism.

Retain Data Responsibly

We retain customer data for as long as necessary to:

  • provide historical attribution and reporting;
  • operate and support the service;
  • troubleshoot and validate data processing;
  • maintain service reliability and security;
  • comply with legal obligations;
  • resolve disputes;
  • follow customer instructions.

Retention periods may differ by data category, service configuration and legal requirement.

Structured attribution, order and reporting records may be retained throughout the customer relationship to provide historical reporting.

Raw event payloads, logs and other operational data may be retained for shorter periods or archived, minimised, de-identified or deleted when they are no longer needed for active service operation.

Following termination, customer personal data will be returned or deleted in accordance with our Data Processing Addendum, subject to legal requirements and ordinary backup lifecycles.

Customer Responsibilities

Data protection is a shared responsibility.

Customers using nVektor are responsible for:

  • maintaining accurate privacy and cookie notices;
  • obtaining any required consent;
  • establishing an appropriate lawful basis for processing;
  • configuring nVektor and connected platforms lawfully;
  • determining which events and identifiers should be collected;
  • honouring end-user choices and privacy rights;
  • ensuring they do not send prohibited, sensitive or unnecessary personal data;
  • complying with applicable advertising and ecommerce platform terms.

nVektor does not provide legal advice and cannot determine whether a customer’s specific implementation complies with every law that may apply to its business.

Our Legal Framework

Our data protection framework includes:

  • Data Processing Addendum, which sets out our binding processor and service-provider obligations;
  • Terms of Service, govern customer access to and use of the nVektor service;
  • Marketing Website Privacy Policy, explains how we handle information collected through our own website and business activities;
  • Cookie Notice, explains the cookies and similar technologies used on the nVektor marketing website;
  • Subprocessor Register, identifies service providers that process customer personal data on our behalf and is available to customers upon request.

Data Processing Addendum

Customers that require a Data Processing Addendum may contact us at:

hello@nvektor.com

Or visit https://nvektor.com/legal/data-processing-addendum

Our DPA addresses:

  • processing roles and instructions;
  • confidentiality;
  • technical and organisational measures;
  • security incident notification;
  • privacy-rights assistance;
  • subprocessors;
  • international data transfers;
  • retention and deletion;
  • compliance information and audits.

Questions About Privacy or Compliance

For questions about nVektor’s privacy, data protection or compliance practices, contact:

Wahecos Commerce Digital, LLC
Email: hello@nvektor.com
Address: 312 West 2nd Street, Casper, WY, USA

This page is provided as a general summary. Where it conflicts with an executed agreement, the applicable Terms of Service, order form or Data Processing Addendum will control.